Phishing and Social Engineering
Know the goal
Social engineering targets people rather than software bugs. Phishing is a common form: messages that look official and urge you to click a link, open an attachment, or share a secret.
Spot common warning signs
- Urgent threats (“account closes today”) or unexpected prizes
- Sender address that almost matches a real brand
- Links that go to unfamiliar domains when you hover or long-press
- Requests for passwords, one-time codes, or remote-access permission
- Attachments you did not expect, especially archives or executables
Respond safely
Do not click the message’s link. Open the official app or type the known website address yourself. Contact the organization through a published phone number or help page—not the contact details in the suspicious message.
Report and contain
Use the provider’s “report phishing” action when available. If you entered a password, change it on a clean device, enable MFA, and check recent account activity. Tell household or teammates if a shared service might be affected.
Comments
One comment per signed-in account. Comments are saved with this page’s URL.